Description
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds read in a kernel component responsible for processing disk images was addressed with improved bounds checking. The flaw, mitigated in recent releases by stricter bounds checking, can be triggered by mounting a specially crafted volume. When exploited, the read may exceed the intended buffer boundaries, allowing an attacker to read arbitrary kernel memory, corrupt critical data structures, or force the operating system to terminate unexpectedly. These effects compromise confidentiality, integrity, and availability at the kernel level and could provide a foothold for further privilege escalation.

Affected Systems

Apple’s macOS is impacted by this issue. The vulnerability exists in releases predating macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6. Any system running an earlier version of these operating systems that processes disk images may be susceptible.

Risk and Exploitability

The CVSS score is 9.8, and the EPSS score is < 1%, indicating a very low, but non‑zero exploitation probability. However, the weakness involves kernel memory corruption, which is treated with high severity. Attackers would need to deliver a malicious disk image and mount it, suggesting the vector is local or requires privileged user interaction; remote exploitation is less likely unless a patch or user script triggers mounting. The lack of CISA KEV marking indicates no confirmed public exploitation as of now, but the potential for privilege escalation or denial of service warrants careful monitoring.

Generated by OpenCVE AI on August 4, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent macOS updates that include Sequoia 15.7.8, Sonoma 14.8.8, or Tahoe 26.6.
  • Disallow or avoid mounting disk images from untrusted or unknown sources until the update is installed.
  • Configure the system to require explicit user confirmation before automatically mounting external or network‑based disk images.

Generated by OpenCVE AI on August 4, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Kernel Out‑of‑Bounds Read via Malicious Disk Image

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read via Malicious Disk Image Causes Kernel Memory Corruption on macOS
Weaknesses CWE-788

Thu, 30 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read via Malicious Disk Image Causes Kernel Memory Corruption on macOS
Weaknesses CWE-788

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T14:11:14.799Z

Reserved: 2026-05-01T22:46:27.818Z

Link: CVE-2026-43773

cve-icon Vulnrichment

Updated: 2026-07-28T14:11:04.780Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:17:01.680

Modified: 2026-07-28T18:06:56.097

Link: CVE-2026-43773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:30:10Z

Weaknesses